Live data from Hacker News

Compromised Linode, thousands of BitCoins stolen

bitcoinmedia.com

171–180 of 249 posts

Re: Compromised Linode, thousands of BitCoins stolen

#171
post #105

" As a respected hosting provider, I hope they do the correct thing and refund me for this liability due to their error. Many people trust Linode, and they have proven themselves as a serious contender for hosting critical sensitive operations on the internet. I would hate to not see them live up to that reputation. " "hosting critical sensitive operations" in particular. If you are doing "critical sensitive operatio…

It's certainly a grey area, but at what point is it safe to assume that if you get hacked, it's not going to be because your ISP got hacked? Say this happened to Amazon and it affected a company like Heroku or dropbox, both users of AWS? Regardless of what terms of service says, I'll bet there's some liability somewhere. And if there's a cut off, maybe linode should advertise that? "Hey, we're cheap, but you get what…

A bank or safe deposit box business will most definitely have clear terms about how liable they are for if something gets stolen.

For a hosting company this is different. Especially because--it's hard to draw a line but I feel it's there--there's a difference between storing sensitive data and storing (what are practically) valuables/money.

I wonder though, I'm not clear on his set up (or business, even), but basically he was literally storing his bitcoin money on a Linode server? Since they're not a bank, nor a safe-deposit service, or are in the business of storing valuables (as opposed to sensitive data). I can't come up with a realworld analogy (they usually break down anyway), but wouldn't you want to wrap this data in an extra layer of encryption or something? It's not that hard to come up with some scheme so that people with root access to the Linode server can't do anything with it either. Since this is about (almost) real money, that's what I'd do.

Re: Compromised Linode, thousands of BitCoins stolen

#172
post #154
post #3

So, a customer service interface was compromised via stolen credentials and used to access various Linode instances. A couple questions that immediately come to mind: 1. Can this interface be accessed from anywhere on the Internet? If so, why? If not, does that mean other systems owned by Linode were compromised as well? 2. Why can customer service representatives access and update servers without the client being no…

Linode will send you a confirmation email if you access the admin panel from a "new" IP. This guy must have had his email address compromised as well. Looks like a class spear-attack.

So far there are 3 people who've reported their Linodes compromised. They all had popular Bitcoin services running on their Linode.

3 compromised emails? Very unlikely. They are all major contributors to Bitcoin, I think they know a little more than using the same password everywhere.

Linode will only send you a confirmation email if you enable the feature, otherwise tough luck. It's also been confirmed by the vice president of Linode to be a fault on their side.

Re: Compromised Linode, thousands of BitCoins stolen

#173
post #172
post #154

Earlier quoted context omitted.

Linode will send you a confirmation email if you access the admin panel from a "new" IP. This guy must have had his email address compromised as well. Looks like a class spear-attack.

So far there are 3 people who've reported their Linodes compromised. They all had popular Bitcoin services running on their Linode. 3 compromised emails? Very unlikely. They are all major contributors to Bitcoin, I think they know a little more than using the same password everywhere. Linode will only send you a confirmation email if you enable the feature, otherwise tough luck. It's also been confirmed by the vice p…

Fair enough. I stand corrected.

More plausible to have broken web UI security than an entire bitcoin-community-wide targetting.

Re: Compromised Linode, thousands of BitCoins stolen

#174
post #165

Earlier quoted context omitted.

Yeah, but could the (ex) coat owner hold the restaurant's landlord liable? Isn't it the restaurant _managers_ problem? I think there's a _lot_ of "grey areas" here, and while I feel sympathy for the guy who's out ~$13k worth of bitcoins, I can't help but think he was "doing the wrong thing" relying on the security of an inexpensive vps to keep them safe…

What would you recommend? Would you say the same thing if he'd been colocating and a data center employee had stolen his bitcoins? Because that seems far more analogous than any restaurant analogy, and I don't see any reasonable way for somebody who's not a huge corporation to avoid this kind of risk. You have to trust somebody at some point unless you're keeping the server locked in your own closet. It seems really…

What do I recommend? I'm really not sure…

Firstly, I'd start asking whether a $19.95/month shared hosting* account is a "reasonable" place to store $13k worth of (effectively) cash. I'd be _very_ careful if I had that sort of folding-money-type-cash on hand, and would under normal circumstances automatically deposit in a bank account to mitigate the risks involved with carrying it around. And I'd usually take steps to not ever have that sort of value of cash build up or be required - the only transaction I've ever done of that sort of value in cash is selling or buying a car from an individual - and that's always been a direct from transaction to the bank type of arrangement.

If I had enough bitcoin value that it'd hurt to lose it, I would not (at least now in hindsight) store that on a machine that other people I don't know/trust have root access to. Maybe I'd keep my wallet on a usb stick in my pocket or in a safe at home? I think though that at somewhere near the $13k value the "right" thing to do is convert it to cash and take advantage of the existing banking system and its time-tested security and insurability.

(* Which is fundamentally what a linode VPS is, at least from anyone with access to the hypervisors point of view.)

Re: Compromised Linode, thousands of BitCoins stolen

#175
post #165

Earlier quoted context omitted.

Yeah, but could the (ex) coat owner hold the restaurant's landlord liable? Isn't it the restaurant _managers_ problem? I think there's a _lot_ of "grey areas" here, and while I feel sympathy for the guy who's out ~$13k worth of bitcoins, I can't help but think he was "doing the wrong thing" relying on the security of an inexpensive vps to keep them safe…

What would you recommend? Would you say the same thing if he'd been colocating and a data center employee had stolen his bitcoins? Because that seems far more analogous than any restaurant analogy, and I don't see any reasonable way for somebody who's not a huge corporation to avoid this kind of risk. You have to trust somebody at some point unless you're keeping the server locked in your own closet. It seems really…

Then he should Colo with a hosting provider with a contract provision that specifically holds them liable for any losses related to problems caused by the host, and enumerates those possible losses beforehand.

Re: Compromised Linode, thousands of BitCoins stolen

#176
post #164
post #156

Earlier quoted context omitted.

I can put a "not responsible for stolen items" sign in my restaurant, but if the coat check employee bolts out the door when you hand them your coat, I'm buying you a new one.

What if the coat was full of diamonds?

In an actual court case, the reasonableness of everyone's actions would be evaluated, but it's hard to imagine a court finding it unreasonable that someone placed data worth $13,000 to them on a respected VPS provider.

That doesn't mean Linode has any legal liability in this case, just that your analogy is off the mark.

Re: Compromised Linode, thousands of BitCoins stolen

#177

Earlier quoted context omitted.

It's not about "don't put anything on a VPS", it's about "don't put money on a VPS."

Or passwords, or medical records, or anything confidential or of value?

I bet people think twice before storing medical records on services like Linode. At least I _hope_ they do?

Re: Compromised Linode, thousands of BitCoins stolen

#178
post #164

Earlier quoted context omitted.

What if the coat was full of diamonds?

In an actual court case, the reasonableness of everyone's actions would be evaluated, but it's hard to imagine a court finding it unreasonable that someone placed data worth $13,000 to them on a respected VPS provider. That doesn't mean Linode has any legal liability in this case, just that your analogy is off the mark.

"it's hard to imagine a court finding it unreasonable that someone placed data worth $13,000 to them on a respected VPS provider."

Really? (I'm reading that as saying you think it _is_ a reasonable thing to store $13k worth of effectively-cash-value in a $19.95/month vps account?)

Does anyone know what regulations like HIPPA or PCI have to say about the security of data stored on managed-by-3rd-party servers like VPSs?

Re: Compromised Linode, thousands of BitCoins stolen

#179

Earlier quoted context omitted.

In an actual court case, the reasonableness of everyone's actions would be evaluated, but it's hard to imagine a court finding it unreasonable that someone placed data worth $13,000 to them on a respected VPS provider. That doesn't mean Linode has any legal liability in this case, just that your analogy is off the mark.

"it's hard to imagine a court finding it unreasonable that someone placed data worth $13,000 to them on a respected VPS provider." Really? (I'm reading that as saying you think it _is_ a reasonable thing to store $13k worth of effectively-cash-value in a $19.95/month vps account?) Does anyone know what regulations like HIPPA or PCI have to say about the security of data stored on managed-by-3rd-party servers like VPS…

First of all, yes, I think it's reasonable.

Second, where are you getting $19.95/month from, anyway? I haven't seen the plan in question mentioned, and even if this particular VPS happened to be Linode's lowest-end, the last time I looked (a while back, granted), slush had multiple large VPSs with Linode.

Third, really, what does the price of the VPS have to do with it? You think as the cost of the VPS goes down, we're entitled to less assurance that an employee isn't going to bolt with our data?

Finally, HIPAA and PCI regulations are ginormously complex, but violations of them almost inevitably cost a hell of a lot more than $13k.

Re: Compromised Linode, thousands of BitCoins stolen

#180
post #93

Earlier quoted context omitted.

where do you keep the key to the crypto fs?

Written on a scrap of paper in your wallet. only the password and no other info should be on the scrap. If you can memorize it, it is a bad password.

Eh, it depends, a random fragment of a very long poem for instance can be quite easy to memorize but at 80-90 words/300-400 characters long is pretty damn secure, doesn't even need to be written down then.
Post reply on HN